CVE-2024-4032 describes a vulnerability in Python's "ipaddress" module where the is_private and is_global properties incorrectly identified certain IPv4 and IPv6 addresses, failing to align with current IANA Special-Purpose Address Registries. This issue affects Python versions prior to CPython 3.12.4 and 3.13.0a6. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and no user interaction required, potentially leading to high confidentiality impact. However, there is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.10.0, < 3.10.15CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.11.0, < 3.11.10CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.12.0, < 3.12.4CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 0, < 3.8.20CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.9.0, < 3.9.20CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024CVE-2024-4032
Oct 8, 2024python: incorrect IPv4 and IPv6 private ranges
Jun 17, 2024Incorrect IPv4 and IPv6 private ranges
Jun 11, 2024